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DAMI-AM 


DEPARTMENT OF THE ARMY 

OFFICE OF THE ASSISTANT CHIEF OF STAFF FOR INTEl-UIGENCE 
WASHINGTON. D.C. 20310 


8 SEP 1981 


SUBJECT: Recommendations for Employment of SECOM Funds Allocated to 
CSS 


STAT 

Chairman, 

Computer Security Subcommittee 
SECOM, NFIB 


lo The purpose of this letter is to comply with your request for a list 
of recommended projects to be funded by the Computer Security Subcom- 
mittee (CSS) o It is our firm belief that CSS funds should be allocated 
only to those projects which will produce an identifiable, tangible pro- 
duct which will have broad Intelligence Community use^ Further, appli- 
cations supported by DIA and the military services should have universal 
value in mil itary intelligence functionso 


2. The most critical requirement facing the entire Intelligence Community 
(IC) today is the need to Redefine and Restructure the Security and 
Protection Attributes Which Support the Automated Handling and Communi- 
cation of Intelligence Information * The multitude of classifications, 
codewords, caveats, control and dissemination restrictions present in the 
IC today have introduced great complexity into the processing and trans- 
mission of vital intelligenceo The proliferation of intelligence systems 
and current planning for their future interface demands careful, judi- 
cious study of this problem and development of a workable, practical, 
hierarchic structure of standard security and protection attributes which 
can be Implemented in the automated Information handling world. I am 
currently working on the first draft of a much more detailed paper on 
this subject and will provide it to you when completed ^ In the meantime, 

I feel very strongly that the subcommittee should identify and support 
this project. Because there is already some interest in solution of this 
problem in t:])p nai-a ^^y el of the Int^lj^ pnrr Tn#TrnnrirT^ 

.Handling Committee. NFlSTit^^uU be made a joint project with that^ 
group o 



3. Next in priority is the need for a broad, definitive study of The 
Threats Against Intelligence Automation o Such a study might well be an 
outgrowth of the compilation activity which DIA RSE-4 now has underway 
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with the Military Intelligence Reserve unit in Texas. If content dictates, 
this product should be produced in two versions; one hopefully at the 
SECRET collateral level for broad, general dissemination, and a second at 
the TOP SECRET SCI level for more restricted IC dissemination. Command- 
and management -lev el attention and Interest must be gained and maintained 
through provision of well-written expositions on the serious threats 
against automated systems. 

4. As an ancillary to The Threats Against Intelligence Automation there 
should be produced, as a separate document if necessary, a serious, lay- 
man language Compromising Emanation Threat Study . Decision-authorities 
in Army and the other services are confronted on a daily basis with the 
requirement to approve or disapprove the design of automated systems at 
both the tactical and strategic levels which must incorporate protection 
against compromising emanations. The credibility of this EMSEC require- 
ment is not now well established, except in the electronic engineer- 
oriented language of NACSEM 5100. There is a demand for a definitive, 
detailed, explanatory threat and countermeasure document which can be 
read, understood and applied by managerial personnel without the need for 
engineer interpretation. Production of this study should be a joint effort 
with the Subcommittee on Compromising Emanations (SCOCE) . 

5. There is also a strong requirement for an authoritative Automation 
Security Dictionary defining all the terms and criteria to be applied in 
clear, precise language. A precedent exists in United States Communica- 
tions Security Board (USCSB 2-17) **Glossary of Communications Security and 
Emanations Security Terms,” October 1974. 

6. Lastly, a requirement exists for the development and promulgation of 
an IC guidance document on the application of Risk Analysis Criteria, 
Procedures, and Techniques for Automation and Communication Systems in the 
Intelligence Community . 

7. I will be happy to elaborate on any of the above recommendations at 
your request. 
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